Information Disclosure |
Overview Information Disclosure may result when internal information is disclosed to the user-agent (browser). These paths can be used in other attacks. Discovery Methodology Attempt to discover if it is possible to cause errors by injecting all input parameters with characters that are reserved in various contexts. Search web page sources (view source) for internal information disclosure. Search for custom administrative pages and administrative consoles such as phpMyAdmin installations. Exploitation Search pages with and without injection. Use the grep feature of Burp-Suite to seach for inappropriate information. Search for known common administrative consoles such as phpMyAdmin installations, Drupal and Wordpress consoles. Videos Warning: Could not reach YouTube via network connection. Failed to embed video. Determine HTTP Methods using Netcat: Visit YouTube Site Warning: Could not reach YouTube via network connection. Failed to embed video. Determine Server Banners using Netcat, Nikto, and w3af: Visit YouTube Site Warning: Could not reach YouTube via network connection. Failed to embed video. Using Nmap to Fingerprint HTTP servers and Web Applications: Visit YouTube Site Warning: Could not reach YouTube via network connection. Failed to embed video. Finding Comments and File Metadata using Multiple Techniques: Visit YouTube Site |